Alice's $140 Million Round and the Real Price of DSPM for AI
A cheque this size is never really about the company that cashes it. It is a market telling you, in the plainest language it has, which categories it now believes are real.
By Katie Delaney · 2026-08-25 · 14 min read
The $140 million signal Alice just sent#
A funding round is not a headline. It is a hundred and forty million reasons somebody believes the category is real.
AI security posture management stopped being a slide in somebody's pitch deck on 25 August 2026, the morning Alice, the AI security company formerly known as ActiveFence, announced a $140 million round led by Apax Digital, with Samsung and SentinelOne joining and Maj Invest, MoreTech and Phoenix Insurance alongside a run of returning backers, according to Tech Startups and confirmed by Bloomberg. Total funding now stands at $280 million, annual recurring revenue is nearing $100 million, and Apax Digital partner Patrick Kane is taking a board seat.
Alice built its reputation on a patient prowl through the underside of the internet: nearly a decade spent as ActiveFence, hunting the coordinated harassment and disinformation campaigns hiding inside major platforms, before turning that same scent for real attacks toward frontier AI. Its proprietary Rabbit Hole dataset, built from real adversarial content rather than synthetic examples, now feeds a 150-strong research team that stress-tests models before release and watches them after, per Alice's own newsroom. "There are infinite ways to break an AI, and you can't defend against something you've never seen," chief executive Noam Schwartz said of the round, a line that reads less like a slogan and more like a job description.

That is the pitch in one cheque: eight of the top ten AI model labs now pay Alice to chase their own blind spots before an attacker does, and the round values the company close to a billion dollars, according to SecurityWeek. For folkfox's cybersecurity clients the headline is not the cheque. It is what a cheque of that size proves about buyer behaviour: enterprises are now budgeting for ai security posture management the way they budget for endpoint protection, and dspm for ai is the line item most likely to appear on next year's renewal alongside it.
Why the round matters more than the round#
A single large raise can always be one investor's enthusiasm running ahead of the market. What makes Alice's cheque worth a slower read is that it did not arrive alone, and the company it keeps this month is the actual story.
Why dspm for ai is the term worth tracking too#
Security borrowed its vocabulary from compliance long before AI arrived, and ai security posture management inherits the structure wholesale from cloud security posture management: discover the estate, score its exposure, prioritise the fix, prove the fix landed. Microsoft folded almost the exact phrase into its own product literature. Its Defender for Cloud documentation is titled, near verbatim, AI security posture management, and describes discovering an organisation's AI Bill of Materials across Azure OpenAI, Amazon Bedrock and Google Vertex AI, then routing the worst exposures through attack path analysis, per Microsoft's own Defender for Cloud documentation. Buyers evaluating that stack increasingly ask for dspm for ai in the same breath.
A cousin term is doing the rounds too. dspm for ai applies data security posture management, originally built to find and classify sensitive data sprawled across cloud storage, to the narrower and stranger problem of data folded into a model's weights or a vector store rather than sitting in a bucket a scanner can see. Gartner's own market guide for dspm for ai, summarised by Cyera, treats it as adjacent rather than identical to ai security posture management: one product line watches what a model can do, the other watches what a model has been fed.
Microsoft Defender for AI Services runs the threat-protection half of the same idea: real-time detection tuned to the failure modes unique to generative systems, sitting inside the same console security teams already use for cloud workloads, per Microsoft's onboarding documentation. That a platform vendor the size of Microsoft ships a dedicated plan under almost the same name is not proof ai model security is settled science, and it has not resolved how dspm for ai and model-side testing divide the invoice. It is proof the market decided the term before the vendors finished agreeing what belongs inside it.
A crowded name for a young category#
Whichever shape a buyer needs, model, agent or data, the umbrella term the market has settled on is still ai security posture management, and that consensus is itself new. A year ago neither that phrase nor dspm for ai existed outside a handful of analyst decks. Five funding rounds, a Microsoft product name and a fast-growing dspm for ai footprint later, it has a scent trail investors are now openly following.
Five rounds, one fortnight: a pattern, not a one-off#
Alice's cheque did not arrive in a quiet week. In the first four days of August 2026 alone, four other vendors closed rounds built on the identical thesis: that AI agents and models are a genuinely new attack surface, and the tooling built for the old one does not reach it. Horizon3.ai closed a $250 million Series E at a valuation past $2 billion, its chief executive saying the company had "earned the right to autonomously pentest the most critical and sensitive networks in the world", per Horizon3.ai's own announcement. Zenity raised $125 million to police what it calls the era of a billion AI agents, backed by Norwest, SoftBank and Hitachi, per Zenity's own newsroom.
Obsidian Security closed an $85 million round at a $1.1 billion valuation to govern non-human identities inside enterprise software, per Obsidian Security, and Oligo Security added $60 million for runtime protection against AI-driven attacks, per SecurityWeek's report on Oligo.
AI Security: Alice raises $140M led by Apax Digital amid AI security concerns. Market Impact: institutional capital flowing into AI security infrastructure; signals enterprise demand for AI governance tools.
Five rounds is not noise. It is a repeated bet placed by different investors on the same shape of company, and the shape is worth seeing side by side rather than headline by headline.
| Company | Round raised | Lead investor | Date |
|---|---|---|---|
| Alice | $140 million | Apax Digital | 25 Aug 2026 |
| Horizon3.ai | $250 million | NightDragon and NEA | 3 Aug 2026 |
| Zenity | $125 million | Norwest | 3 Aug 2026 |
| Obsidian Security | $85 million | Crescent Cove Advisors | 4 Aug 2026 |
| Oligo Security | $60 million | Ballistic Ventures led syndicate | 4 Aug 2026 |
Read the bars the way a fox reads a hedgerow at dusk, not for the tallest gap but for the pattern of gaps repeating. Five different lead investors reached the same conclusion inside three weeks: NightDragon and NEA on Horizon3.ai, Norwest on Zenity, Crescent Cove on Obsidian, a Ballistic Ventures led syndicate on Oligo, and Apax Digital on Alice. That is not five founders selling the same story. It is five investment committees independently underwriting the same risk, dspm for ai included.
What the evidence actually shows#
Money moving is not the same as a problem being proven, so it is worth separating the two. On the demand side, Gartner puts current adoption of dedicated AI security platforms at under 10% of enterprises in 2025, and projects that share will pass half by 2028, a curve reported by Security Boulevard. That gap, nine in ten enterprises still unprotected against a threat their own security teams increasingly name as real, is the addressable market every one of this month's five rounds in ai security posture management is pricing in, dspm for ai among the fastest-moving line items inside it.
On the threat side, the case is not just vendor marketing. A July 2026 study tested commercial AI agents, including Claude, Gemini and GPT-based systems, against what its authors call agent data injection: attacks that hide instructions inside the ordinary web pages, files and tool outputs an agent is asked to process. The researchers found the technique a realistic threat rather than a laboratory curiosity, per the arXiv study. That is the exact mechanism ai security posture management tooling exists to catch: not a model behaving badly on its own, but a model faithfully following an instruction it was never supposed to trust.
The honest caveat#
None of this is settled science. The waffle above states a measured survey figure, not a folkfox estimate, and it is labelled that way for a reason: a chart that quietly presents a modelled shape as a headcount is worse than no chart at all. What is measured is the adoption gap and the academic finding. What is inferred, reasonably but still inferred, is that five rounds in three weeks means investors read that gap the same way.
The vendor thicket buyers now have to cross#
Ask five analysts to name the ai-spm vendors worth a shortlist and expect five overlapping but not identical lists, because the category is still arguing with itself about its own edges. Some ai-spm vendors, Alice among them, lead with red-teaming and runtime monitoring of the model itself. Others, Zenity and Obsidian among them, lead with governing what an agent is allowed to touch once it is already inside a business system. A buyer chasing dspm for ai wants a third shape again, one that starts with the data rather than the model or the agent.
| Layer | What it watches | Example from this month |
|---|---|---|
| The model | Red-teaming and runtime monitoring of a model's own outputs | Alice |
| The agent | What an autonomous agent is permitted to touch or execute | Zenity, Obsidian Security |
| The data | Sensitive data reachable by, or embedded in, an AI system | dspm for ai specialists |
A sensible shortlist checks the free layer first. If Microsoft Defender for AI Services already ships inside the console a security team logs into every morning, the specialist ai-spm vendors on the list need to earn their invoice by doing something that baseline genuinely cannot: deeper red-teaming, a broader dataset of real attacks, or coverage of models running outside Azure entirely, and a dspm for ai specialist earns its own invoice the same way.
What actually separates a platform from a rebadged scanner#
The tell is evidence, not adjectives. A vendor that can name its dataset, state its red-team cadence and point to a customer running at a comparable scale is selling a platform. A vendor that reaches for words like robust, best-in-class or seamless without a single figure attached is usually selling a rebadged scanner with a new logo, and the gap between the two only shows up once you ask for the number. That is exactly the standard dspm for ai vendors get held to as well.
What this means for your positioning#
For folkfox clients selling into this category, security vendors, MSSPs, and any B2B brand that has to reassure an enterprise buyer its own AI use is governed, the lesson of this fortnight is not that AI security posture management is crowded. It is that it is credible, and credible categories reward the vendor who can prove the claim rather than the vendor who states it loudest.
State plainly, in one self-contained sentence, how your product tests and monitors the AI it uses or sells. A generative summary can quote a sentence. It cannot quote a vague promise.
Cite a dataset, a red-team cadence, or a named framework such as dspm for ai tooling, rather than an adjective like robust.
Before pitching a client on AI governance, audit which of your own tools already run as agents nobody in security signed off on.
Under 10% of enterprises run dedicated AI security tooling today. The gap is the opportunity, and it narrows as Gartner's own curve steepens toward 2028.
None of that is a copywriting exercise on its own. It sits underneath real campaign work: the SEO and GEO discipline that gets a vendor's posture claims cited rather than paraphrased, the brand strategy that decides which layer of the vendor thicket a company actually competes in, and the content marketing that turns a red-team cadence into something a buyer can actually read before a call.
The pattern repeats across folkfox's own cybersecurity coverage this week. Microsoft's own Entra ID patch showed how fast a posture-management category can be forced to prove itself against a live flaw, and Fortinet's acquisition of Virtue AI's red-teaming tools shows the same consolidation instinct arriving from the buyer side rather than the investor side. Regulation is not standing still either: the EU AI Act's robustness requirements are already shaping which vendors get shortlisted in Europe, and folkfox's own writing on a real jailbreak that hopped models mid-attack is the practical argument for why testing has to be continuous, not a one-off certificate.
The question every AI-adjacent B2B brand should be ready to answer#
If a prospect asked your business today how you test, monitor and govern the AI you run or sell, could you answer in one sourced sentence, the way Microsoft's documentation does, rather than a paragraph of reassurance with nothing to click on? That is the actual test this month's five rounds set, for the vendors raising the money and for every company that has to sell alongside them. folkfox works with cybersecurity brands and regulated fintech companies on exactly that answer, built to survive both a human reader and the AI summary standing between you and them. If that is the gap in your own positioning, talk to us before your competitor's next funding round does the talking for them.
Frequently asked questions#
What does ai security posture management actually cover?
It is the discipline of discovering every AI model, application and agent an organisation runs, scoring their exposure, and prioritising fixes, the same logic cloud security posture management applies to infrastructure, now aimed at generative systems and the agents and data around them.
How is dspm for ai different from ai security posture management?
dspm for ai focuses narrowly on sensitive data reachable by, or embedded inside, a model or vector store. ai security posture management is broader: it covers a model's own behaviour, an agent's permitted actions and the surrounding infrastructure, with data exposure as one part of the picture rather than the whole of it.
Does Microsoft Defender for AI Services replace a dedicated ai security posture management tool?
It covers real-time threat detection for AI workloads inside Microsoft's own cloud console, which is a genuine baseline. Specialist ai security posture management vendors typically go further: deeper red-teaming, coverage of models running outside Azure, and datasets built from real attacks rather than synthetic ones.
What should buyers look for among ai-spm vendors?
Evidence over adjectives: a named dataset, a stated red-team cadence, customer references at a comparable scale, and clarity about whether the product watches the model, the agent, or the data feeding both.
What are ai security posture management tools?
Software that discovers an organisation's AI models and agents, tests them against adversarial attacks such as prompt injection and jailbreaks, monitors their behaviour once deployed, and reports the resulting risk so a security team can prioritise fixes.
Why did investors put over half a billion dollars into AI security in one month?
Because Gartner puts current adoption of dedicated AI security platforms under 10% of enterprises while projecting over half will run one by 2028, a gap five separate investment committees priced as durable demand rather than a passing trend.
What is ai model security?
It is the practice of testing an AI model itself against misuse: jailbreaks, prompt injection and adversarial manipulation, before and after deployment. Alice, Horizon3.ai and the other vendors in this month's funding wave all sell some version of ai model security, though they draw its edges differently.
Read more on this topic#
Entra ID Scored a Perfect Ten, and Identity Security Posture Management Caught It in Time
The same posture-management logic, tested against a live maximum-severity Entra ID flaw rather than a funding round.
Read the pieceAI security grew a deadline before it grew evidence
Why the EU AI Act's robustness requirements are already shaping which AI security vendors get shortlisted in Europe.
Read the pieceMDR Services Just Grew a Second Set of Watchful Eyes
Fortinet bought Virtue AI's agent red-teaming tools weeks after its founders left, the same consolidation instinct from the buyer side.
Read the pieceAI security testing and the jailbreak that went shopping for a weaker model
A real jailbreak that switched models mid-attack, the practical case for continuous testing over a one-off certificate.
Read the pieceReady to own dspm for ai in your own market?
folkfox builds positioning, content and campaigns for security vendors and MSSPs racing to own dspm for ai and ai model security before a rival says it louder.